Skip to main content

Help us improve the Digital Marketplace - send your feedback

X - LAB LIMITED

LabReach

LabReach is an OrderComms solution that provides a web-based portal enabling users to order diagnostic tests directly into laboratory LIMS systems across the Labgnostic network. Test results are automatically streamed back to the portal, with configurable email notification options to keep users informed of result availability.

Features

  • Web-based portal accessible from any modern browser without software installation
  • Direct integration with laboratory LIMS systems across the Labgnostic network
  • Real-time test ordering workflow from portal to laboratory systems
  • Automated results streaming from laboratories back to the portal
  • Configurable email notification system for result availability alerts
  • Secure data transmission between portal, laboratories, and users
  • User authentication and access control mechanisms
  • Audit trail of orders and result delivery

Benefits

  • Streamlines diagnostic test ordering, reducing administrative burden
  • Eliminates manual data entry errors through LIMS integration
  • Faster test result turnaround through automated delivery
  • Centralised visibility of orders and results
  • Automated notifications for timely result awareness

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at enquiries@x-labsystems.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 0 3 3 8 0 7 1 4 3 5 8 8 0 4

Contact

X - LAB LIMITED Commercial Department
Telephone: 07787656851
Email: enquiries@x-labsystems.co.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
N/A
System requirements
N/A - we cater for the buyers requirements.

User support

Email or online ticketing support
Yes
Support response times
Online ticketing support is provided 9:00 and 17:30 Monday to Friday, excluding Bank holidays. Within these hours the tickets are responded to as follows:
1) Urgent severity - Before the start of the next Business Day;
2) High severity - Before the end of the next Business Day;
3) Medium - 2 Business Days;
4) Low - 3 Business Days
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
No
Web chat support
No
Onsite support
No
Support levels
We provide one standard support level for the LabReach service. This support model applies to all customers equally and is designed to ensure consistent service quality, transparency, and fair use. Support, maintenance, and general software upgrades are included as part of the contracted service.

Support includes:
- Access to a service desk during Normal Business Hours
- Incident management, service requests, and change requests handled in line with ITIL principles
- Defined incident severity levels with documented target resolution times
- Planned maintenance management
- Access to out-of-hours third-line engineering support triggered via automated monitoring (no customer-initiated service desk outside Normal Business Hours).
Customers are provided with a named Account Manager, who acts as the primary commercial and service liaison. This role supports onboarding coordination, service reviews, and future service expansion planning. Technical support is delivered via the service desk and specialist engineering teams as required
Support available to third parties
No

Onboarding and offboarding

Getting started
X-Lab prides itself on excellent customer service with each of our LabReach customers assigned a dedicated Account Manager. The Account Management team is an integral part of the organisation and works closely with the Onboarding and Support team as part of the wider Customer Success function. The Account Managers work closely with the Sales team and are introduced to new LabReach customers during the sales process. Prior to customers' onboarding to the LabReach service, we ensure a contract is agreed and that all organisations joining the network comply with information governance (in the form of a Data Protection Agreement). The Account Manager will work closely with the customer to maintain engagement, agree a utilisation plan, deal with any escalations, communicate service developments, and continually review the customer experience. We provide a welcome pack containing a high-level overview of what to expect during the LabReach onboarding process (including supporting documentation, prerequisites, required stakeholders, key milestones, and a bespoke onboarding plan). Training and support are offered online however there is scope for training to be delivered onsite. Testing scripts are provided to the customer to validate testing ahead of sign off and cutover into production.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
  • Other
Other documentation formats
  • Word
  • Excel
End-of-contract data extraction
We don't explicitly extract/remove data when a contract ends. We have a Retention Policy which is available on request. Data is removed from the production system after 4 months by default and will be removed from the archive after a further 2 years. Customers can reduce their retention period for production to a shorter period (we recommend no less than ~1 month, but this could be shorter if required). Upon request from an exiting customer a final data extract can be provided. This is a complex process as we would need to obtain agreement from all third party organisations that hold data sharing agreements with the off-boarding customer.
End-of-contract process
LabReach customers usually renew their contract at the end of the subscription term. Should a customer decide to end the contract, the termination terms form part of the contractual documentation. The dedicated Account Manager would work with the customer to ensure any outstanding invoices have been paid and would facilitate an off-boarding plan with the relevant teams. The tasks carried out by the X-Lab team include the deletion of the connection profiles, the decommissioning of the Customer VPN and the removal of web access configuration. The team would be required to wait until the archive period elapses and delete the laboratories. End users would need to be removed from the Service desk and CRM system. Users would also need removing from any service communications. The customers would be expected to liaise with other LabReach/Labgnostic partners to communicate and manage the process, although the team at X-Lab could assist and advise where necessary.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Onboarding/Offboarding documents are accessible for customers to read in PDF format. If a document is shared requesting information or for collaboration documents are shared as ODF. Documents can also be shared in HTML format. All of our document formats are accessible across all devices including documents containing logos, images, and charts, and can be printed or stored by recipients.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
LabReach is accessed through a web-based portal using any supported modern browser, with no client-side software required.
Laboratory Connectivity:
LabReach uses the Labgnostic platform for LIMS integration:

Pre-built interfaces for common LIMS systems using vendor HL7 specifications
LIMS-agnostic specification for custom development where vendor modules unavailable

User Setup:

Existing Labgnostic customers: Use existing LIMS interface configuration
New laboratories: Configure LIMS interface as a performing laboratory

Laboratory administrators use a separate web interface for configuration and user management.
Accessibility standards
None or don’t know
Description of accessibility
Current Accessibility Approach:
LabReach is built using modern web development practices and industry-standard design libraries that include accessibility features such as keyboard navigation, ARIA attributes, and semantic HTML elements.
Accessibility Features:

Keyboard navigation support throughout the application
Semantic HTML structure for screen reader compatibility
Responsive design adapting to different viewport sizes and devices
Clear visual contrast and readable typography

Compliance Status:
We have not conducted formal WCAG 2.1 compliance testing or accessibility audits at this time. Organisations with specific accessibility requirements should contact us to discuss their needs and evaluate suitability.
Accessibility testing
None.
API
No
Customisation available
No

Scaling

Independence of resources
LabReach is built to scale horizontally and vertically making best use of available managed cloud services. Given the nature of the service providing a network of customers together, no guarantee can be made that an abnormally high load from one customer would not affect another.

Analytics

Service usage metrics
Yes
Metrics types
On request we can provide transaction volumes for each customer, and can provide more detailed analysis (e.g. turnaround times or transaction volumes segmented by test type and partner lab) on request. This would require work from Engineers to provide.
Reporting types
Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
LabReach does not currently provide a self-service data export function within the web application.
Customers requiring data exports should contact their Account Manager or the Support team. Upon request, we can provide data exports in JSON format containing the customer's order and result data.
Export requests are processed on a case-by-case basis to ensure data security and that only authorised personnel receive access to their organisation's information.
Data export formats
  • CSV
  • Other
Other data export formats
JSON
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • HL7

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
We aim to ensure that the service is available throughout the Subscription Term for 99.7% of the time. There is currently no mechanism for refunds.
Approach to resilience
We use Azure's cloud native redundancy and resilience tooling to ensure our platform is spread over multiple data centres and regions within the UK.
Outage reporting
Update banners via the service desk and email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Public key authentication (including by TLS client certificate)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Azure AD group membership with conditional access and MFA.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Currently under going certification for ISO 27001.
Information security policies and processes
We employ a suite of ~20 information security policies and have built our ISO27001 ISMS policies as part of phase 1 of our audit.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We ensure that security requirements are captured as far left in the SDLC as possible to ensure we have resources to appropriately remediate. All changes are developed using pair programming, and scanned for static code analysis including infrastructure as code static analysis (policy-as-code)
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Vulnerabilities identification is done by our vulnerability management tool and reported back every 6 hours. Vulnerabilities are then logged automatically as tickets for the respective team to remediate within our SLAs, with reporting on adherence to SLAs fed up to senior management.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Logging from endpoints, IaaS , PaaS, SaaS tools are ingested by our SIEM and monitored by our SOC on a 24/7 basis with proactive threat hunting activities conducted monthly.
Incident management type
Supplier-defined controls
Incident management approach
Our incident management approach is holistic as part of our risk management and BC/DR management approach. All suspected or confirmed security incidents are reported to the GRC team & SLT who triage and follow the predefined playbooks for various common incidents. Any live incidents have a PIR conducted with the Lessons Learned captured and remediated within SLAs. Incident Reports are provided to the customer within 48 hours of closure of the incident.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
Yes
Connected networks
  • Scottish Wide Area Network (SWAN)
  • Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
3%
Between £500,001 and £1,000,000
6%
Between £1,000,001 and £2,500,000
9%
Between £2,500,001 and £5,000,000
12%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E940d951-581e-4e45-9cfd-61a86de643d4
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
F16f8b35-62c2-4efd-9490-bdf7ea61050e
Other security certifications
Yes
Any other security certifications
Data Security and Protection Toolkit

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at enquiries@x-labsystems.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.